Summary
Togoder Security scanned the npm package @ethereumjs/tx@4.2.0 on Oct 4, 2026. An AI review of 20 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/baseTransaction.js | safe | No malicious patterns detected; this is a legitimate Ethereum transaction base class from @ethereumjs/tx with standard cryptographic and validation logic. |
| dist/constants.js | safe | No malicious patterns detected; the file only exports numeric constants related to EIP-4844. |
| dist/eip1559Transaction.js | safe | No malicious patterns detected; this is a standard EIP-1559 Ethereum transaction implementation from @ethereumjs/tx with only cryptographic and validation logic. |
| dist/eip2930Transaction.js | safe | No malicious patterns detected; the file is a legitimate Ethereum EIP-2930 transaction implementation with no exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/fromRpc.js | safe | The code is a benign transaction parameter normalization utility with no malicious patterns detected. |
| dist/index.js | safe | No malicious patterns detected; the code is a standard TypeScript-compiled index file for Ethereum transaction types with no data exfiltration, credential harvesting, or dynamic code execution. |
| dist/legacyTransaction.js | safe | No malicious patterns detected; the code is a legitimate Ethereum legacy transaction implementation using standard cryptographic libraries. |
| dist/transactionFactory.js | safe | No malicious patterns detected in the transaction factory code; it is a standard Ethereum transaction handling module with no signs of exfiltration, credential harvesting, or other suspicious behavior. |
| dist/types.js | safe | No malicious patterns detected |
| dist/util.js | safe | No malicious patterns detected; the code is a standard Ethereum access list utility with no network, filesystem, process, or dynamic execution activity. |
| src/baseTransaction.ts | safe | This is a legitimate Ethereum transaction base class implementation with no malicious patterns detected. |
| src/constants.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/eip1559Transaction.ts | safe | No malicious patterns detected |
| src/eip2930Transaction.ts | safe | No malicious patterns detected; the file is a legitimate Ethereum EIP-2930 transaction implementation from the @ethereumjs/tx library with no exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| src/fromRpc.ts | safe | No malicious patterns detected |
| src/index.ts | safe | This file only re-exports transaction classes and types from a well-known Ethereum library, with no malicious patterns, side effects, or suspicious behavior. |
| src/legacyTransaction.ts | safe | No malicious patterns detected. |
| src/transactionFactory.ts | safe | No malicious patterns detected |
| src/types.ts | safe | No malicious patterns detected; the file contains only TypeScript type definitions, interfaces, enums, and pure type-guard functions with no runtime execution, network, filesystem, or process activity. |
| src/util.ts | safe | No malicious patterns detected; the code is a legitimate Ethereum access-list utility with standard validation and conversion logic. |
Affected version ranges
None of the 2 scanned versions of @ethereumjs/tx are flagged high or critical. The latest scanned version, 5.4.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @ethereumjs/tx
Frequently asked questions
Is @ethereumjs/tx safe to use?
Our AI source review of @ethereumjs/tx@4.2.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @ethereumjs/tx contain malware?
No malware was identified in @ethereumjs/tx@4.2.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @ethereumjs/tx checked?
Togoder Security downloaded the published npm package and had an AI model read its 20 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @ethereumjs/tx together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @ethereumjs/tx@4.2.0, cost nothing.